Remote code execution vulnerability in Microsoft SharePoint Server allowing unauthenticated attackers to execute arbitrary code.
Microsoft RCE CRITICAL9.8 Multiple critical vulnerabilities in Langflow AI framework allowing remote code execution through crafted API requests.
Langflow RCE CRITICAL9.8 Authentication bypass vulnerability in PAN-OS management interface leading to remote code execution.
Palo Alto Networks Auth Bypass CRITICAL9.4 Remote code execution in FortiSandbox through deserialization of untrusted data.
Fortinet RCE HIGH8.8 Remote code execution via specially crafted search queries in Splunk Enterprise.
Splunk RCE HIGH8.6 Remote code execution through RPC interface in llama.cpp AI inference server.
llama.cpp RCE CRITICAL9.8 Deserialization vulnerability in Apache ActiveMQ Jolokia interface allowing remote code execution.
Apache Deserialization HIGH8.8 Remote code execution via Apache Tomcat Cluster communication ( tribes channel).
Apache RCE HIGH8.6 Authentication bypass in cPanel WHM leading to full root-level remote code execution.
cPanel Auth Bypass → RCE CRITICAL9.8 Remote code execution in Apache Syncope through JEXL expression evaluation.
Apache RCE HIGH8.1 Remote code execution in nginx through crafted HTTP/2 frames (rift module).
nginx RCE HIGH8.4 Remote code execution in React2Shell framework through server-side rendering injection.
React2Shell RCE CRITICAL9.8 Command injection in Edimax router web interface allowing full device takeover.
Edimax RCE HIGH8.8 Command injection in Edimax router management interface.
Edimax RCE HIGH8.8 Command injection vulnerability in Edimax device firmware.
Edimax RCE HIGH8.8 Information disclosure in Edimax router configuration endpoints.
Edimax Info Leak MEDIUM6.5 Authenticated command injection in Edimax router admin panel.
Edimax RCE HIGH8.8 Command injection via setdmzcfg endpoint in TotoLink A8000RU router.
TotoLink RCE HIGH8.8 Buffer overflow in Telnet NEW-ENVIRON option handling.
netkit Buffer Overflow HIGH8.1 Buffer overflow in Telnetd LINEMODE SLC option processing.
netkit Buffer Overflow HIGH8.1 Remote code execution in Laravel Ignition via phar:// deserialization (historically significant, still relevant for unpatched deployments).
Laravel RCE CRITICAL9.8 Remote code execution in KMW CCTV camera systems through authenticated command injection.
KMW RCE CRITICAL9.8 Authentication bypass in Cisco SD-WAN Manager leading to remote code execution.
Cisco Auth Bypass → RCE CRITICAL9.4 Remote code execution via OGNL injection in Apache Struts multipart parser.
Apache RCE CRITICAL9.8 Authentication bypass in Ivanti Connect Secure VPN allowing unauthenticated remote code execution.
Ivanti Auth Bypass → RCE CRITICAL9.8 Stack-based buffer overflow in Ivanti Policy Secure allowing unauthenticated RCE (actively exploited in the wild).
Ivanti Buffer Overflow CRITICAL9.8 Stack-based buffer overflow in Ivanti Connect Secure SSL VPN, exploited by UNC17885 (Chinese state actor).
Ivanti Buffer Overflow CRITICAL9.0 Critical command injection in PAN-OS GlobalProtect gateway (CVSS 10.0), exploited by UNC4841 Chinese state actor.
Palo Alto Networks Command Injection CRITICAL10.0 Command injection in Ivanti Connect Secure and Policy Secure web components, chained with CVE-2023-46805 for mass exploitation.
Ivanti Command Injection CRITICAL9.8 Authentication bypass in Ivanti Connect Secure, chainable with CVE-2024-21887 for unauthenticated RCE.
Ivanti Auth Bypass HIGH8.2 Authentication bypass in FortiGate SSL VPN leading to remote code execution on the device.
Fortinet Auth Bypass → RCE CRITICAL9.6 Format string vulnerability in FortiOS fgfmd daemon allowing remote code execution via specially crafted packets.
Fortinet Format String CRITICAL9.8 Out-of-bounds write in FortiOS SSL VPN, exploited in the wild by Volt Typhoon (Chinese state actor).
Fortinet Out-of-Bounds Write CRITICAL9.8 Sensitive information disclosure in Citrix NetScaler ADC and Gateway (Citrix Bleed), heavily exploited by LockBit ransomware affiliates.
Citrix Buffer Overflow CRITICAL9.4 Authentication bypass in PAN-OS management web interface allowing privileged access to restricted resources.
Palo Alto Networks Auth Bypass HIGH8.8 Remote code execution in Apache HTTP Server via mod_rewrite regex buffer overflow.
Apache RCE HIGH8.6 Remote code execution in Microsoft Exchange Server via SSRF in Outlook Web Access (ProxyShell variant).
Microsoft Exchange Server Microsoft RCE CRITICAL9.8 Deserialization of untrusted data in Microsoft SharePoint Server allowing remote code execution.
Microsoft SharePoint Server Microsoft Deserialization HIGH8.8 Remote code execution in Windows SMB Server via crafted SMB packet (Wormable, EternalBlue-class).
Microsoft Remote Code Execution CRITICAL9.8 Buffer overflow in Windows LDAP Server allowing unauthenticated remote code execution (ZeroLogon-class).
Microsoft Buffer Overflow CRITICAL9.8 Deserialization vulnerability in Progress Telerik UI for ASP.NET AJAX allowing remote code execution.
Progress Software Deserialization CRITICAL9.8 Remote code execution via SpEL expression injection in Spring Framework parameter binding.
VMware RCE HIGH8.6 Remote code execution in Apache OFBiz via pre-authentication deserialization.
Apache RCE CRITICAL9.8 Privilege escalation in Kubernetes API server via crafted TokenReview request allowing cluster-admin impersonation.
Kubernetes Privilege Escalation HIGH8.4 Server-side request forgery and path traversal in Next.js middleware allowing file read on the server.
Vercel Path Traversal HIGH8.1 Authentication bypass in Grafana dashboard sharing allowing unauthenticated access to private dashboards.
Grafana Labs Auth Bypass HIGH8.8 Remote code execution in GitLab CE/EE via project import deserialization vulnerability.
GitLab RCE CRITICAL9.8 Lua sandbox escape in Redis allowing authenticated users to execute arbitrary code on the server.
Redis Ltd Lua Sandbox Escape HIGH8.1 Remote code execution in Elasticsearch Watcher via Groovy script injection.
Elastic RCE HIGH8.4 Remote code execution in Confluence Server via OGNL injection in velocity templates.
Atlassian RCE CRITICAL9.8 Remote code execution in Zimbra Collaboration Suite via postmail.jsp file upload vulnerability.
Zimbra Collaboration Suite Synacor RCE CRITICAL9.8 Remote code execution in Jenkins via sandbox bypass in Groovy deserialization.
Jenkins RCE HIGH8.8 Deserialization vulnerability in Apache Tomcat JDBC connection pool allowing RCE via JNDI injection.
Apache Deserialization HIGH8.4 Denial of service in Apache MINA via crafted FTP command sequence causing infinite loop.
Apache Denial of Service MEDIUM6.5 Unauthenticated command injection in D-Link DIR-823 router via Set_sysTimezone handler.
D-Link Command Injection CRITICAL9.8 Unauthenticated command injection in TP-Link Archer AX73 via debug menu endpoint.
TP-Link Command Injection CRITICAL9.8 Authentication bypass in Netgear Orbi router admin panel via hardcoded credentials.
Netgear Authentication Bypass CRITICAL9.8 Command injection in ASUS router firmware via custom DNS field in web GUI.
ASUS Command Injection HIGH8.8